Loading component...
At a glance
By Adam Turner
With modern threats often targeting human frailties and breaches of security policies instead of technological weaknesses, the cybersecurity burden can fall on finance professionals — who are heavily targeted due to their access and authority.
Today’s accounting and finance professionals face a growing onslaught of attacks as cybercriminals leverage AI to take phishing, business email compromise, invoice fraud and deepfakes to the next level.
Along with deceiving victims into transferring funds, scammers target sensitive business information and access to critical systems that can bring a business to its knees.
The cost of cybercrime to Australian large businesses reached an average of A$202,700 per incident in 2024–25, marking a 219 per cent year-on-year increase, according to the Australian Signals Directorate’s Annual Cyber Threat Report.
Preparation is key
Historically, boards treated cybersecurity as a technical checkbox relegated to the IT department. Today, expanding regulatory frameworks such as Australia’s Security of Critical Infrastructure Act 2018 and APRA’s CPS 230 standard mandate direct board oversight and formal executive-level risk management strategies.
Despite the growing risk and impact of cyber attacks, finance leaders are often unprepared and unaware of where their responsibilities lie, says Tyler Wise FCPA, partner in accounting and business advisory at Findex.
“Lack of preparedness for an attack is still a very common issue in our profession. Not just being prepared to defend against attacks, but being prepared to respond when those defences are breached.
“We are constantly advised to have a ‘breached mindset’, but we rarely see this in practice until a breach actually occurs and lessons are learned the hard way,” he notes.
Cyber resilience
A common cybersecurity model is the “three pillars” of People, Process/Policy and Technology, which work in unison to underpin “cyber resilience”. This resilience ensures not only the capability to defend against attacks, but also to reduce the impact of successful attacks and weather the storm.
This three-pillar approach means that finance professionals are required to be across business-critical processes and policies, from cyber governance and operational resilience to Cyber Security Incident Response Plans and disclosure obligations.
An incident response plan includes internal and external communication processes in the event of an incident, as well as the roles, responsibilities, accountabilities and authorities of personnel and teams.
In the aftermath of an attack, Wise says that a lack of preparedness, inadequate processes and insufficient governance can pose longer-lasting reputational risk to a business than the actual attack itself.
Finance leaders do not need a computer-science degree in order to help stakeholders support cyber resilience, he believes. Yet they do require the insight to ask the right questions about issues like data residency, backup procedures and incident response plans.
“For example, this means not only ensuring that backup procedures are in place with multiple copies, but also that backups are tested to ensure they can actually be relied on in the event of a cyber incident,” Wise says.
“Ultimately, finance professionals do not need to have all the technical answers, but they do need to be able to show that cybersecurity defence is a priority and is being factored into decisions and processes.”
Production credit
Banner image urbazon via Getty Images

